Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-18875

HIGH NVD
CVSS Score 7.3
Severity HIGH
Published Sep 23, 2026
Vendor unknown

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

References